Use of uninitialized resource in FortiOS and FortiProxy - CVE-2023-37930
Published: October 24, 2025
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to usage of uninitialized resources within the SSL-VPN webmode. A remote authenticated user can send specially crafted requests to the SSL-VPN websocket, trigger uninitialized usage of resources and perform a denial of service attack or execute arbitrary code on the device.
Affected software
FortiProxy
How to mitigate CVE-2023-37930
FortiProxy - addressed in versions 7.0.13, 7.2.7, 7.4.0